The Dutch Data Protection Authority fined Uber 824,990,000 euros because drivers were fully automatically deactivated without genuine human intervention, causing loss of income. Organisations automating income-determining decisions must now check whether a human can really assess and change the outcome, and whether data subjects are sufficiently informed about profiling.
According to the European Data Protection Board's publication, the matter concerned drivers who were temporarily or permanently deactivated on suspicion of fraud and after persistently low customer ratings. The case arose from complaints by French drivers and covered the period 2018 to 2022. The French regulator CNIL, which acted as a cooperating authority, confirms that the deactivations came about automatically, without human intervention, and that blocked drivers could no longer carry out rides and therefore could no longer earn an income.
What exactly did the Data Protection Authority establish in the Uber case?
The regulator established two distinct violations. First, Uber took fully automated decisions to deactivate drivers, with significant consequences for their income and without a human actually assessing the outcome. Second, Uber insufficiently informed the drivers about this automated decision-making and the underlying profiling.
CNIL's explanation makes clear why the income impact weighed heavily: a driver who is blocked cannot drive and loses their earning opportunity. The deactivation significantly affected the drivers economically because blocked drivers could no longer carry out rides or earn income, bringing the Article 22 safeguards for decisions with legal or similarly significant effects into focus.
Why are the missing human intervention and the deficient profiling information two separate violations?
Our analysis is that they are two distinct compliance questions: one concerns the decision process and human intervention, while the other concerns the information provided about automated processing and profiling. The first concerns the decision process itself: where Article 22 applies to a solely automated decision with legal or similarly significant effects, the safeguards include the right to obtain human intervention, express a point of view and contest the decision. The second concerns the duty to inform: data subjects must receive appropriate and comprehensible information about relevant automated decision-making or profiling, including meaningful information about the logic involved, its significance and the envisaged consequences for them.
The Court of Justice of the European Union stated in its SCHUFA judgment of 7 December 2023 that meaningful information must be given about the logic of automated decision-making, plus its significance and envisaged consequences. In our assessment, this helps clarify why the Uber decision's human-intervention and information issues should be analysed separately: reporting that profiling exists is not enough; the explanation should provide meaningful information about the processing, its significance and its envisaged consequences so that affected people can understand the decision and use the available challenge route.
A second observation of our own: a claim that there is a human in the loop only counts if that person can genuinely assess the matter, has the authority to change the outcome and is given enough time and knowledge to do so. A formal signature after the fact, or a staff member who in practice only confirms what the model already determined, is not meaningful intervention. This follows from the sources, but the practical application is our interpretation.
What does this fine mean for organisations that automate income-determining decisions?
Our analysis: because the regulator deemed the Uber deactivations unlawful in the circumstances examined, organisations that automatically determine access, suitability or payment should assess whether comparable Article 22 and transparency risks arise in their own decision flows; because Uber insufficiently informed drivers about profiling, a privacy statement that merely mentions the existence of algorithms may not provide the meaningful information required in a comparable context, so the compliance function should explain the relevant logic, significance and consequences in text that data subjects can understand; and because the fine concerned the absence of genuine human intervention, a nominal reviewer should not be treated as sufficient, so the responsible manager should appoint reviewers with mandate, expertise and enough time, and record that mandate before an income-determining decision takes effect. Our analysis: because affected people should have a meaningful route to contest a covered decision, an objection procedure should be usable in practice. Organisations should also consider retaining the input data, model or rule version, decision path, reviewer action and objection outcome. This ties in with the GDPR accuracy principle in automated processing and with the broader line of making AI transparency testable with evidence about purpose and intervention. You will find more background in our topic hub on AI privacy and GDPR.
Which measures prevent an automated decision from becoming unlawful?
Our recommended control framework is threefold: do not issue an irreversible outcome on the basis of a model alone, ensure a reviewer who can genuinely change the outcome, and record what happened. In our assessment, this helps make evidence of human intervention and transparency reviewable after the fact.
- Map every automated decision about suitability, fraud, assessment or access and determine whether it has a legal effect or similarly significant effect.
- Prohibit irreversible or income-determining outcomes from being issued solely by a model.
- Appoint reviewers with authority, expertise and sufficient time to examine the individual case and change the outcome.
- Retain the input data, the model or rule version, the decision path, the reviewer's action and the outcome of the objection, so that you can record which automated decision was checked by whom.
- Give data subjects a comprehensible explanation of the logic and consequences, plus a usable route to contest the decision.
The Uber decision does not introduce a new rule into the GDPR, nor does it prohibit all automated decisions. It does make clear that transparency and human intervention are two separate requirements, and that neither can be dealt with by a formal solution when people's income is at stake.
Sources and references
Sources: The article draws on the European Data Protection Board's publication about the Dutch Data Protection Authority's fine, CNIL's explanation and the SCHUFA judgment of the Court of Justice of the European Union.